CVE-2002-1188
Summary
| CVE | CVE-2002-1188 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-11 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading." |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Explorer | 5.0.1 | All | All | All |
| Application | Microsoft | Internet Explorer | 5.0.1 | sp1 | All | All |
| Application | Microsoft | Internet Explorer | 5.0.1 | sp2 | All | All |
| Application | Microsoft | Internet Explorer | 5.5 | All | All | All |
| Application | Microsoft | Internet Explorer | 5.5 | sp1 | All | All |
| Application | Microsoft | Internet Explorer | 5.5 | sp2 | All | All |
| Application | Microsoft | Internet Explorer | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Security Bulletin MS02-066 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| 'LEVERAGING CROSS-PROTOCOL SCRIPTING IN MSIE' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| www.ciac.org/ciac/bulletins/n-018.shtml | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| ISS X-Force Database: ie-object-read-tif (10665): Microsoft Internet Explorer OBJECT tag could be used to read TIF folder name | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Patch, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Microsoft Internet Explorer Object Tag Temporary Internet File Folder Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.